[ubuntu/resolute-updates] bind9 1:9.20.24-1ubuntu0.1 (Accepted)

Timo Aaltonen tjaalton at ubuntu.com
Wed Aug 5 15:36:55 UTC 2026


bind9 (1:9.20.24-1ubuntu0.1) resolute; urgency=medium

  * New upstream release 9.20.24 (LP: #2126464)
    - Updates:
      + Remove the ineffective TCP fallback after repeated UDP timeouts.
      + Fall back to TCP on receipt of a UDP response with mismatched query ID.
      + Limit glue records cached from a referral per nameserver.
      + Reject a CNAME response to a DS query promptly.
      + Spread cache cleanup probabilistically to avoid CPU spikes and slow
        queries when the cache approaches its memory limit.
      + Record query time for all dnstap responses.
      + Optimize TCP source port selection on Linux via IP_LOCAL_PORT_RANGE.
      + Use the zone file's basename as origin in dnssec-signzone and
        dnssec-verify.
      + Implement seamless outgoing TCP connection reuse with pipelined queries
        per connection capped at 256.
      + Randomize nameserver selection.
      + Make catalog zone names and member zones' entry names case-insensitive.
    - Bug fixes:
      + Remove other RRsets at the same name when caching a CNAME.
      + Fix nxdomain-redirect combined with dns64.
      + Fix DNS64 owner-name case after a DNAME restart.
      + Clear the REDIRECT flag when it isn't needed.
      + Disable output escaping in bind9.xsl.
      + Fix crash on badly configured secondary signer missing the file entry.
      + Fix possible crash on concurrent TKEY DELETE for the same key.
      + Reject RRSIG records covering meta-types ANY, AXFR, IXFR, MAILA, MAILB.
      + Fix possible race condition during zone transfers.
      + Fix named crash when processing SIG records in dynamic updates.
      + Fix zone verification of NSEC3 signed zones.
      + Prevent a crash when using both dns64 and filter-aaaa.
      + Fix assertion failure when processing catalog zones with invalid TSIG
        key name.
      + Prevent malicious DNSSEC zones from exhausting validator CPU by
        rejecting DNSKEYs with oversized RSA public exponent.
      + Fix rndc-confgen aborting on HMAC-SHA-384/512 keys above 512 bits.
      + Prevent crafted queries from degrading RRL performance via
        per-process keyed hash.
      + Prevent rare named crash when notifies are cancelled.
      + Stop delv from aborting on malformed query name.
      + Fix crash when reconfiguring while an NTA is being rechecked.
      + Fix bug in allow-query/allow-transfer catalog zone custom properties.
      + Fix memory leak in catalog zones.
      + Fix suppressed missing-glue check in named-checkzone.
      + Reject record sets too large to serve in DNS at storage time.
      + Fix intermittent named crashes during asynchronous zone operations by
        enforcing loop affinity.
      + Count temporal DNSSEC validation problems as validation attempts.
      + Fix possible deadlock in RPZ processing.
      + Fix crash triggered by rndc modzone on a zone from a configuration
        file.
      + Fix processing of empty catalog zone ACLs.
      + Fix crash triggered by rndc modzone on a zone that already existed in
        NZF file.
      + Fix potential resource leak during resolver error handling.
      + Fix handling of key statements defined inside views.
      + Fix use-after-free in dns_client_resolve() triggered by a DNAME
        response.
      + Fix assertion failure triggered by non-minimal IXFRs.
      + Fix crash when retrying a NOTIFY over TCP.
      + Improve fetch loop detection for an in-domain nameserver with expired
        glue.
      + Fix dnstap logging of forwarded queries.
      + Fix stale answer being served on multiple upstream failures when
        following CNAME chains.
      + Fail DNSKEY validation when supported but invalid DS is found..
      + Fix stack memory corruption when importing invalid SKR file.
      + Return FORMERR for queries with EDNS Client Subnet FAMILY field set to
        0.
      + Fix inbound IXFR performance regression where very large IXFR
        transfers were much slower than in 9.18.
      + Fix implementation of BRID and HHIT record types.
      + Fix implementation of DSYNC record type.
      + Fix response policy and catalog zones to work with INCLUDE directive.
    - Remove CVE patches fixed upstream
      + CVE-2026-1519-*.patch
      + CVE-2026-3104-*.patch
      + CVE-2026-3119-*.patch
      + CVE-2026-3591-*.patch
      [Fixed in 9.20.21]
      + CVE-2026-3039-*.patch
      + CVE-2026-3592-*.patch
      + CVE-2026-3593-*.patch
      + CVE-2026-5946-*.patch
      + CVE-2026-5947.patch
      + CVE-2026-5950-*.patch
      [Fixed in 9.20.23]

Date: 2026-07-15 13:58:12.105176+00:00
Changed-By: Lena Voytek <lena.voytek at canonical.com>
Signed-By: Timo Aaltonen <tjaalton at ubuntu.com>
https://launchpad.net/ubuntu/+source/bind9/1:9.20.24-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list